The Bug Report – October Edition

Your Cyber Security Comic Relief

Apache server version 2.4.50 (CVE-2021-42013)

Why am I here?

Regardless of the origins, you’ve arrived at Advanced Threat Research team’s monthly bug digest – an overview of what we believe to be the most noteworthy vulnerabilities over the last month. We don’t rely on a single scoring system like CVSS to determine what you need to know about; this is all about qualitative and experience-based analysis, relying on over 100 years of combined industry experience within our team. We look at characteristics such as wormability, ubiquity of the target, likelihood of exploitation and impact.  If you don’t agree with these picks, we encourage you to write a strongly worded letter to your local senator. In lieu of that, we present our top CVEs from the last month.

Apache: CVE-2021-41773 and CVE-2021-42013

What is it?
2 CVES / 1 Vuln – It appears Apache struggled a bit with this latest critical vulnerability, where it took two tries to fix a basic path traversal bug, which was introduced while patching last month’s SSRF mod_proxy vulnerability. As path traversal bugs do, this allows unauthorized users to access files outside the expected document root on the web server. But wait, there’s more! This can lead to remote code execution provided mod-cgi is enabled on the server.

Who cares?
A quick Shodan scan told me there are at least 111,000 server admins that should care! With Apache being the second largest market share holder of implemented webservers, there is a good chance your organization is using it somewhere. It’s always important to consider both internal and external facing assets when looking at your exposure. Apache is even commonly used as an embedded webserver to other applications and should be reviewed for use in any installed 3rd party applications. Oh yeah – and if you overlook an instance you have installed somewhere, this IS currently being actively exploited in the wild – no pressure.

What can I do?
Oh! I know, use Microsoft IIS! If you’re not ready to completely abandon your webserver implementation, I suggest updating to Apache 2.4.51. Remember to avoid version 2.4.50 as it does not patch both vulnerabilities. If you have been an astute system admin and followed the Apache documentation using the default and pretty darn secure “require all denied” directive for all files outside the document root, kudos to you! Although patching is still highly recommended, you are not immediately vulnerable.

The Gold Standard
We recognize in some special cases patching is harder than compiling gcc from source, so McAfee Enterprise has you covered; we have been detecting path traversal attacks in our Network Security Platform (NSP) like it was going out of style since 1990 (and it was).

Win32k Driver: CVE-2021-40449

What is it?
Ain’t nothin’ free anymore! Except kernel module addresses on your Windows machines, thanks to Microsoft Windows CVE-2021-40449. This vulnerability is a use-after-free in the NtGdiResetDC function of the Win32k driver and can lead to attackers being able to locally elevate their privileges.

Who cares?
Are you currently reading this from a Microsoft Windows machine? Using Microsoft Server edition in your cloud? Local attacks are often given lower priority or downplayed. However, it is important to recognize that phishing attacks are still highly successfully as an initial point of entry, facilitating a need for privilege escalation bugs to obtain higher level access. So, unless you are a hardcore Linux and Mac-only shop, you may want to patch since this is actively being exploited by cybercriminals, according to our friends at Kaspersky.

What can I do?
That boring Microsoft patch Tuesday thing still works, or you could just use a superior operating system like FreeBSD.

The Gold Standard
Have you checked out the latest version of McAfee Enterprise ENS lately? Detecting exploitation and cybercriminal activity is sort of its thing, assuming you have grabbed the latest signatures.

Apple iOS: CVE-2021-30883

What is it?
An integer overflow vulnerability in the iOS “IOMobileFrameBuffer” component can allow an application to execute arbitrary code with kernel privileges. This has additionally been confirmed to be accessible from the browser.

Who cares?
Since Apple still reportedly holds 53% market share of all smartphone users, statistically speaking your organization should care too. It only takes one bad apple to hack your entire network, and with reported active exploitation in the wild it might happen sooner than you think.

What can I do?
You should be sensing a common theme in this section – and, in this case, you actually can take action! Stop reading this, plug that mobile device into a power source, and install the latest version of Apple iOS.

The Gold Standard
Since you stopped reading and updated already, congrats!

The post The Bug Report – October Edition appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Annual Cost of Child Identity Fraud Almost $1Bn

Annual Cost of Child Identity Fraud Almost $1Bn

New research published today by Javelin Strategy & Research puts the annual cost of child identity theft and fraud in the United States at nearly $1bn.

The 2021 Child Identity Fraud study authored by Tracy Kitten, director of fraud & security at Javelin Strategy & Research, analyzed factors that put children at the highest risk of identity theft and fraud. 

Risk factors examined for the research included behaviors, characteristics, and social media platforms. 

The study found that children who use Twitch (31%), Twitter (30%), and Facebook (25%) were most likely to have their personal information exposed in a data breach.

Another key finding was that more than 1.25 million children in the United States became victims of identity theft and fraud in the past year. Resolving the situation cost the average family more than $1,100 and was a slow process. 

Chillingly, the report revealed that over half of all child identity theft and fraud cases involve children ages 9 and younger, and that most (70%) victims know their perpetrators. 

“One of the most eye-opening findings from our research was just how much risk children are exposed to when they are not supervised online,” said Kitten.

“Add to that nearly 90% of the households with internet access say they have children on social media, and the picture our findings paint quickly becomes dark, grim, and scary,” said Kitten.

Journalist and cybersecurity subject expert Kitten said criminals used social media to access vulnerable children. 

“Predators and cybercriminals lurk in the wings of all social media platforms, waiting for the moment to prey on overly trusting minors who may not fully understand safe online behavior.”

Javelin advised families to limit and monitor the use of social media and messaging platforms by minors and to be on the lookout for cyber-bullying. 

“Platforms that allow users to direct/private message (DM), friend, or follow other users via public search pose the greatest concern,” said a company spokesperson.

Parents were urged not to share their children’s information on social media and to set positive online safety examples to their children by practicing such behaviors themselves.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FTC Updates Safeguards Rule

FTC Updates Safeguards Rule

The United States Federal Trade Commission (FTC) has tightened the security standards that financial institutions must comply with when handling consumer data.

Financial institutions will be required to explain their information-sharing practices and designate a single qualified individual to oversee their information security program.

The change is part of an update to the FTC’s Safeguards Rule that was announced in a joint statement by FTC Chair Lina M. Khan and Commissioner Rebecca Kelly Slaughter.

Five main modifications to the existing Standards for Safeguarding Customer Information were contained in a Final Rule issued by the commission.

The first adds provisions designed to provide covered financial institutions with more guidance on developing and implementing specific aspects of an overall information security program. It specifies safeguards, including access controls and encryption, and adds mechanisms designed to ensure that employee training and oversight are effective. 

It states that “while the current Rule requires financial institutions to undertake a risk assessment and develop and implement safeguards to address the identified risks, the Final Rule sets forth specific criteria for what the risk assessment must include and requires that the risk assessment be set forth in writing. 

“As to particular safeguards, the Final Rule requires that they address access controls, data inventory and classification, encryption, secure development practices, authentication, information disposal procedures, change management, testing, and incident response.”

The second modification is designed to improve the accountability of financial institutions’ information security programs, while the third exempts financial institutions that collect less customer information from certain requirements.

Under the fourth, the definition of “financial institution” has been expanded to include entities engaged in activities that the Federal Reserve Board determines to be incidental to financial activities. It also adds “finders” – companies that bring together buyers and sellers of a product or service – within the scope of the Rule.

The fifth change included in the Final Rule defines several terms and provides related examples.

Khan and Slaughter said the new consumer protection measure was inspired by recent widespread data breaches, including the Equifax data breach in 2017, which exposed the information of 147 million Americans. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#WebSummit2021: Thierry Henry Launches Platform to Tackle Online Bullying

#WebSummit2021: Thierry Henry Launches Platform to Tackle Online Bullying

Thierry Henry today announced a partnership with sports brand PUMA to create a platform and campaign that will highlight online hate crime and encourage people to do good by taking on tasks to fight against online abuse. The not-for-profit platform is called ‘The Game of our Lives’ (GOL) and tasks will include actions such as petitions and protests.

Thierry Henry, a former striker for Arsenal and France, took to the stage at Web Summit in Lisbon, Portugal, to talk about the online hate that led to him disabling his social media accounts in March 2021. “We need to come together to make the platforms accountable for what is happening on their platforms.” Modestly, Henry said, “I am nobody on my own. I may be the captain [of GOL], but we need lots of captains. That’s something football taught me,” he shared.

Henry was not shy about attributing blame to social media platforms, which he insists are “doing nowhere near enough to tackle online abuse,” and “generate money from hate. When they want to do something, they do it,” he said. “They have an algorithm when it has an impact on their pockets. It’s about willingness.” Clearly, Henry stated that social media platforms could do something about it, but they are unwilling.

However, he told Infosecurity Magazine’s editor, Eleanor Dallaway, that accountability for creating a safer, kinder online space is on “all of us. It is about us being positive and helping each other. Ask yourself, what are we going to do? There’s no more time for negativity.”

“We have to make an impact,” he continued, “to help people to heal.”

“We need to come together to make the platforms accountable for what is happening on their platforms”Thierry Henry

Dylan Ingham, a co-founder of Game of our Lives, describes the platform as a “toolbox of social action. The first task is self-learn. Look at yourself before you start to judge others. It’s not about pointing the finger at the latest villain. It’s about all of us collectively holding each other accountable.”

Henry explained that the issue of online hate goes beyond racism. “The problem I have is that sometimes when I do interviews and people see the color of my skin, they assume I’m only talking about racism.” Henry’s passion for making a difference and stamping out online hate does not discriminate. It’s about the broader issue of online hate, affecting so many minorities and groups.

The goal of The Game of our Lives is to “establish a place where people can come together to turn intention into action.” Adam Petrick, global director of brand and marketing at Puma, shares the project’s objectives – 50 clubs on board and 30 million users. The initiative’s focus will be on prevention, healing and justice.

Henry did acknowledge that there is a lot more awareness and action in The Premier League now compared to what “there was in my time. But still, it could and should be more. The way the football world is moving, though, I can’t complain about that.”

Both Henry and Petrick were keen to present the message that “you should not be stopped by online hate. We want everyone to feel like they belong. The message is not ‘don’t become a footballer’. It’s more ‘don’t get on social media.’”

“The long-term goal is getting rid of online hate, and as a collective we can get there faster,” concluded Henry.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyberversity Helps Budding Cyber Pros

Cyberversity Helps Budding Cyber Pros

California next-gen SIEM and XDR company Exabeam has launched an initiative to help cybersecurity job seekers connect with industry professionals. 

Exabeam announced its free Cyberversity scheme on September 29 as “an interactive educational experience meant to increase diversity and help close the skills gap in the cybersecurity industry.”

Under the initiative, cybersecurity students, recent graduates, and those interested in working in the field of cybersecurity are given a chance to learn directly from Exabeam’s security experts and other established industry professionals through a series of virtual panels and Q&As.

Topics covered in the sessions include cybersecurity career expectations, job-hunting techniques and identifying technical and non-technical opportunities in today’s market.

Cybersecurity experts who have already committed to the program include professionals from organizations such as Canadian Tire, Castra, Chevron Federal Credit Union, and Meissner Filtration.

“We are trying to solve two problems: get people interested in a career in cybersecurity and increase minority representation throughout the industry,” said Michael DeCesare, CEO and president of Exabeam. 

“We want to raise awareness and create opportunities to help address the talent shortage, bring diverse perspectives to our industry, and ensure global organizations are well defended against the growing number of sophisticated adversaries.”

The first two sessions took place last month, and the next session is scheduled for Monday, November 8. 

Exabeam’s Tamara Shephard said that she was “happy to report that the connections students are making with our panelists have been worthwhile.”

She said: “Students have already started to make connections for internships and interviews.”

Now Exabeam is on a mission to publicize the existence of the Cyberversity scheme and its other free career-boosting resources so that more cybersecurity career hopefuls can take advantage of them.

“We are trying to make additional inroads at universities and colleges, so that more students know about our scholarships and high-paid internships as well,” said Shephard. 

Describing the company’s intentions for the future of its Cyberversity, Shephard said: “We will be planning future Q&A sessions with an expanded partners list, so that students meet people from many various cybersecurity companies. We will also be planning sessions that cover interview and resume preparation.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

56% of UK Businesses Plan to Hire a CISO

56% of UK Businesses Plan to Hire a CISO

More than half (56%) of UK businesses plan to employ a chief information security officer (CISO) in the next 6-24 months to help protect them from surging cyber-attacks. This is according to a survey of 251 information security and IT professionals across 250 UK companies conducted by cloud provider Fastly.

The study revealed that only a quarter of businesses currently have a CISO, although there is significant variation across different industries. For example, 75% of organizations in the construction/engineering sector employ a CISO, followed by local/national government (60%) and aerospace (50%).

There was also a lack of clarity regarding the role and purpose of CISOs within organizations. For example, nearly a third (31%) of respondents believe CISOs should have an in-depth understanding of all areas of IT. Additionally, 23% said CISOs are stretched too thinly, 22% believe they are overworked, and 19% feel they are not good enough value for money.

Worryingly, a quarter claimed that CISOs are often blamed for things that aren’t their fault.

The respondents were also asked what they believed would be the security issues that would be costliest for UK businesses over the next five years. Of most concern were malware-based attacks (31%), followed by denial of service attacks (26%), attacks targeting known vulnerabilities (25%), attacks targeting unknown vulnerabilities (24%) and attacks exploiting the misconfiguration of an associated cloud service (24%).

As well as the growing interest in employing CISOs, 21% of businesses want to invest further in cybersecurity professionals and 18% expressed the need to address the impact of remote working on company and employee security moving forward.

Sean Leach, chief product architect at Fastly, commented: “Hiring a CISO is a crucial step in tackling the security threats facing organizations. However, they need to ensure this isn’t just a box-ticking exercise and that they fully embed their CISO into the organization. This will come from a joint investment in both dedicated personnel, with clear and defined roles, paired with robust and adequate security tools.”

“These findings show that, while businesses are beginning to understand how growing their digital offering will increase potential threats they still need to increase the security offerings that protect those technologies, otherwise the results can be catastrophic.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Most Computer Code Compilers Vulnerable to Novel Attacks

Most Computer Code Compilers Vulnerable to Novel Attacks

Most computer code compilers are at risk of ‘Trojan source’ attacks in which adversaries can introduce targeted vulnerabilities into any software without being detected, according to researchers from the University of Cambridge.

The paper, Trojan Source: Invisible Vulnerabilities, detailed how weaknesses in text encoding standards such as Unicode can be exploited “to produce source code whose tokens are logically encoded in a different order from the one they are displayed.” This leads to very difficult vulnerabilities for human code reviewers to detect, as the rendered source code looks perfectly acceptable.

Specifically, the weakness was observed in Unicode’s bi-directional (Bidi) algorithm, which handles displaying text that includes mixed scripts with different display orders, such as Arabic – which is read right to left – and English (left to right). Unicode currently defines more than 143,000 characters across 154 different language scripts.

The researchers noted that in some cases, Bidi override control characters enable switching the display ordering of groups of characters. 

Most programming languages allow these Bidi overrides to be put in comments and strings, which developers largely ignore. This enables targeted vulnerabilities to be inserted into source code without detection.

The authors Nicholas Boucher and Ross Anderson explained: “Therefore, by placing Bidi override characters exclusively within comments and strings, we can smuggle them into source code in a manner that most compilers will accept. Our key insight is that we can reorder source code characters in such a way that the resulting display order also represents syntactically valid source code.”

“Bringing all this together, we arrive at a novel supply-chain attack on source code. By injecting Unicode Bidi override characters into comments and strings, an adversary can produce syntactically-valid source code in most modern languages for which the display order of characters presents logic that diverges from the real logic. In effect, we anagram program A into program B.”

The researchers added that Bidi overrides characters through the copy-and-paste functions on most modern browsers, editors and operating systems. Therefore, “any developer who copies code from an untrusted source into a protected code base may inadvertently introduce an invisible vulnerability.”

While there is currently no evidence that threat actors have utilized these types of attacks, the authors warned of the need for new security controls to counter this danger. They stated: “As powerful supply-chain attacks can be launched easily using these techniques, it is essential for organizations that participate in a software supply chain to implement defenses.

“We have discussed countermeasures that can be used at a variety of levels in the software development toolchain: the language specification, the compiler, the text editor, the code repository, and the build pipeline. We are of the view that the long-term solution to the problem will be deployed in compilers.”

Commenting on the research, Tim Mackey, principal security strategist at the Synopsys CyRC, said: “We’ve seen a variety of novel attacks on software supply chains in 2021, and this is another example of how the trust placed in development processes can be exploited. Teams intrinsically trust their developers, but developers are human and even the best developers can’t be expected to know all the nuances of how code libraries function. 

“When in doubt, they’ll search the internet for examples. Those examples might just be exactly what’s needed to solve the problem, with a result of the found code being copied into the application. While legal teams have been concerned about the potential licensing liability surrounding copied code, an attack using Unicode bidi overrides should concern security teams since that perfect code might only look perfect to the human eye, but instead contain code representing the launch point for an attack that will ultimately be distributed by the application owner.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains